Your message dated Tue, 01 Sep 2026 16:19:03 +0000
with message-id <[email protected]>
and subject line Bug#1146359: fixed in pdfio 1.6.5+dfsg-1
has caused the Debian Bug report #1146359,
regarding pdfio: CVE-2026-77220
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1146359: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146359
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: pdfio
Version: 1.6.3+dfsg-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for pdfio.
CVE-2026-77220[0]:
| PDFio before 1.6.5 contains a dangling pointer vulnerability in the
| dictionary string-formatting function that stores a pointer to a
| stack-local buffer in the document dictionary without copying the
| string value. In multi-threaded or pooled-request environments,
| attackers or concurrent users can trigger stack memory reuse across
| requests, causing cross-tenant document content corruption by
| silently overwriting one caller's dictionary string values with
| another caller's data.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-77220
https://www.cve.org/CVERecord?id=CVE-2026-77220
[1]
https://github.com/michaelrsweet/pdfio/commit/22b9afc800c5833f9e851e35938972bd4c76a357
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: pdfio
Source-Version: 1.6.5+dfsg-1
Done: Bastian Germann <[email protected]>
We believe that the bug you reported is fixed in the latest version of
pdfio, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Bastian Germann <[email protected]> (supplier of updated pdfio package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 01 Sep 2026 17:30:57 +0200
Source: pdfio
Architecture: source
Version: 1.6.5+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Printing Team <[email protected]>
Changed-By: Bastian Germann <[email protected]>
Closes: 1146359
Changes:
pdfio (1.6.5+dfsg-1) unstable; urgency=medium
.
* New upstream version 1.6.5+dfsg (Closes: #1146359, CVE-2026-77220)
Checksums-Sha1:
34ace0bb5aa59c1d2aabbbceae27c342f47e3c41 1961 pdfio_1.6.5+dfsg-1.dsc
6d9e5ca05e244835d3c639fdc2bde93132f36c37 5825892 pdfio_1.6.5+dfsg.orig.tar.xz
80139399700368e3cf31eb08b0d8966ba20eaa49 9224 pdfio_1.6.5+dfsg-1.debian.tar.xz
c65ccbe12d5038a66baa9755742eb8c28ea4d00b 5002
pdfio_1.6.5+dfsg-1_source.buildinfo
Checksums-Sha256:
5f376c5a90ac6a1c4b8d2af53eee84626ef12e6e23b5ce329063c546b8f90a84 1961
pdfio_1.6.5+dfsg-1.dsc
749f55b0a9bcfe7a2d42c1482990c507d81ec37deec1e102a5e6d344f88c403c 5825892
pdfio_1.6.5+dfsg.orig.tar.xz
0ef6b74b39fd15db2a82521e4019d0ecbeee463e98ace49370588589bb714a90 9224
pdfio_1.6.5+dfsg-1.debian.tar.xz
bbb4cb91d0bbd66f21e851b671fb05abf016d7f2a517b34a9bdb5462127dd4dd 5002
pdfio_1.6.5+dfsg-1_source.buildinfo
Files:
8e587913b02c0a9ad52b5c69439fc3cd 1961 libs optional pdfio_1.6.5+dfsg-1.dsc
811fcc6462ca2b46f21d7d44f850389e 5825892 libs optional
pdfio_1.6.5+dfsg.orig.tar.xz
5dcf2958ad4e39aceddc8f02495140eb 9224 libs optional
pdfio_1.6.5+dfsg-1.debian.tar.xz
11629743cc2aa7426ce4ebaa0193cd44 5002 libs optional
pdfio_1.6.5+dfsg-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmqW8T4QHGJhZ2VAZGVi
aWFuLm9yZwAKCRAfXHqLRVZDFK02C/43cjCNtubyNX9iR+0HDQXsek9P5f52QAl0
MJ8JyIGFaAnc7zSR1MiObzkJHYJqgBR7P3SAnsf25EdvH7xYZjSoK2LWiF6wWNKx
q35KpI8v7nbQVTT16lpiVT7BLaLTzhoZLwQu2qrrSCY7NRZGBVT/TWYmHtRKXVDO
ey0o5U2i0L/DieRJAKIZuYqIWZ8KdlZKLxxjTM9C00HMICczSXVujCXBCLCoO3Oh
8S1MoLT8sZGc4wK6HMDdyzarmPjA9t9rAiSK/Xq5Ujzj2gi7WrFjVkLXl6bdqj6j
NjrzBgffFn6bNpOsOBPvrXPJFBcLc9kThP0Y9+kJLDoLwj5l9SG1LfCGsf15U57r
rowFZpLJPBL86IJNxBxaxJfmgkMhIrII0AkSpwCCxp9x2yLGzD/qjyBTNuiklwhs
CpR4LnvECgHyu1JPDaztImusGo1pXY675fc6iUf0Co40CeDe7/IsenI91O9gIpWl
nFFm+e8m+qkvpbyOf4YuC8Rx7SEnc9Q=
=0xad
-----END PGP SIGNATURE-----
pgpc0fxKd0kgn.pgp
Description: PGP signature
--- End Message ---